eMASS
eMASS (Enterprise Mission Assurance Support Service) is the DoD's official web-based application for managing the Risk Management Framework process. It's the system of record for RMF packages — you use eMASS to document your system's security controls, upload artifacts, track POA&M items, and move through the authorization workflow.
eMASS is where your System Security Plan, assessment results, risk acceptance decisions, and ATO documentation all live. If you're involved in getting a DoD system authorized, you'll spend significant time in eMASS entering data, uploading evidence, and managing the authorization workflow.
Why It Matters
eMASS proficiency is essential for anyone managing DoD system authorizations. Understanding the workflow and data requirements upfront prevents delays and rework in the authorization process.